Good morning,
I have been receiving a notable even in ES that states there are default accounts at rest on a certain search head. No other search heads are popping for this notable event. The message states that a default account allows for authentication. The account is "halt' and "admin"I have tried so many things to fix this; locking password, disabling account by setting the age to expire the account,etc; nothing seems to work. I have verified the /etc/passwd file, permissions on sbin/halt and etc/passwd,, and any configurations withing these files or locations as applicable but not sure where else to go from there to fix this. settings. Does anyone have any clue how to remediate this error?
Thank you,
The CS is looking for events from the Compute_Inventory.Default_Accounts data set where 'enabled' is not zero or "false", 'status' is not "Degraded", 'shell' is not "*nologin" or "*false". and the user is not 'root'. Fix any of those and the account should no longer appear.
Thanks for the feedbaack! I have tried several things to disable the account, change the expiration, changed to "nologin" in sbin, disabled password, and expired the account with "chage" commnad. Still receiving the notable event. So what would I need to check besides this and where would I check it on the server in question? What would I need to change about this account to make this stop?
Thanks again, I appreciate any help you can provide.
mgiddens
I don't know enough about Windows user administration to answer.